spotipremium[.]com[.]br
“Spotify Premium APK v9.1.0.490 Baixar [MOD Desbloqueado]”
Resumen de las pruebas
Analysis of the domain spotipremium.com.br indicates it was actively impersonating legitimate services to distribute modified Android applications, specifically targeting users seeking premium software. The domain, registered on January 10, 2025, through Cloudflare, Inc., resolved to the IP address 104.21.10.230, hosted on Cloudflare's infrastructure (AS13335). At the time of assessment, the domain was offline, with no SSL certificate present, increasing the risk of man-in-the-middle interception or data exposure during any prior active phase. The page title, 'Spotify Premium APK v9.1.0.490 Baixar [MOD Desbloqueado]', explicitly advertised a modified version of Spotify Premium, suggesting the site was designed to lure users into downloading unauthorized or malicious APK files.
While the domain is flagged as impersonating Amazon in some threat intelligence sources, the page title does not reference Amazon, indicating potential misclassification or a broader campaign targeting multiple brands. The domain appears on one security blocklist and was flagged by 14 of 95 security vendors on VirusTotal, reinforcing its malicious classification. Infrastructure analysis reveals the domain used Cloudflare nameservers (itzel.ns.cloudflare.com and ricardo.ns.cloudflare.com), a common tactic to obscure hosting origins and evade takedowns. The Gridinsoft trust score of 0/100 further corroborates the domain's high-risk status.
Defenders should treat this domain as part of a distribution network for unauthorized or trojanized applications. Network-level blocking of the IP 104.21.10.230 and monitoring for related domains using Cloudflare infrastructure is recommended. Given the domain's current offline status, historical logs should be reviewed for prior interactions, and users should be alerted to the risks of sideloading modified APKs from untrusted sources.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.